CVE-2025-52613 PUBLISHED

HCL BigFix Service Management (SM) is affected by use of a vulnerable component

Assigner: HCL
Reserved: 18.06.2025 Published: 06.05.2026 Updated: 06.05.2026

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 4.6

Product Status

Vendor HCL
Product BigFix Service Management (SM)
Versions Default: unaffected
  • Version 23 is affected

References

Problem Types

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE